Uploaded image for project: 'Hadoop Common'
  1. Hadoop Common
  2. HADOOP-17563

Update Bouncy Castle to 1.68 or later

    XMLWordPrintableJSON

Details

    • Incompatible change
    • bouncy castle 1.68+ is a multirelease JAR containing java classes compiled for different target JREs. older versions of asm.jar and maven shade plugin may have problems with these. fix: upgrade the dependencies

    Description

      Bouncy Castle 1.60 has Hash Collision Vulnerability. Let's update to 1.68.

      Bouncy Castle 1.60 has the following vulnerabilities. Let's update to 1.68.

      for anyone backporting this, note that recent bouncy castle jars are incompatible with older versions of asm.jar, and so older versions of spark.

      Attachments

        Issue Links

          Activity

            People

              pj.fanning PJ Fanning
              tasanuma Takanobu Asanuma
              Votes:
              0 Vote for this issue
              Watchers:
              10 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 3h
                  3h